Risk Detections
This report lists the risk detections Microsoft Entra ID Protection has raised, with the most recent first. Each row is a single detection rather than a user, so one account under investigation may appear several times with different detection types and timings.
Table Details
The properties returned are for the Graph resource type riskDetection. For more information on the properties please see the Graph documentation.
The Location column is a button rather than plain text. Selecting it opens a Location Details dialog plotting the detection on a map, with the city, state and country listed alongside, which is usually the quickest way to judge whether a detection is a genuine anomaly or the user travelling.
Filters
Users at Risk
Detections still open and not yet acted on.
Confirmed Compromised
Detections an administrator has confirmed as a genuine compromise.
Confirmed Safe
Detections an administrator has marked as legitimate activity.
Remediated
Detections resolved by the user meeting a remediation requirement, such as a self-service password reset.
Table Actions
Research Compromised Account
Opens the Compromise Remediation tab for the account the detection relates to, where the usual indicators of compromise are gathered in one place.
More Info
Opens the Extended Info flyout with the full details for the selected row.
Risk state is held against the user rather than the individual detection, so marking a user as safe or compromised in Entra ID Protection changes the state shown on every detection for that account. The Risky Users page is where a user's overall risk is reviewed and dismissed.
Entra ID Protection needs Entra ID P2 licensing to report detections in full. Tenants without it see limited or no detection data, so an empty table means the feature is unavailable rather than that no risk was detected.
Feature Requests/Ideas
We value your feedback and ideas. Please raise any feature requests on GitHub.
Last updated
Was this helpful?

